Fortinet white logo
Fortinet white logo

Hardware Acceleration

Change log

Change log

Date

Change description

February 21, 2023

Deleted an incorrect statement about NP7 support for SSL VPN encryption from Network processors (NP7, NP6, NP6XLite, and NP6Lite).

February 8, 2023

Added all relevant options and corrected the information about the NP7 hash-config option, see hash-config {src-dst-ip | 5-tuple | src-ip}. Added a note about setting the hash-config for the FortiGate-3500F and 3501F to FortiGate 3500F and 3501F fast path architecture.

New section: FortiGate 3200F and 3201F fast path architecture.

February 7, 2023

The dedicated management CPU feature is supported by the FortiGates with the NP6XLite (SOC4) processor. This information has been added to Improving GUI and CLI responsiveness (dedicated management CPU).

January 4, 2023

Corrected information about NTurbo support and interface policies, see NTurbo offloads flow-based processing.

Corrected the documented default values for many of the individual traffic types monitored by NP7 HPE, see NP7 HPE for individual traffic types.

New sections:

November 8, 2022

Described support for creating LAGs between interfaces connected to different NP6 processors for FortiGates with multiple NP6 processors and no internal switch fabric. For more information, see Increasing NP6 offloading capacity using link aggregation groups (LAGs). Assigning an NP7 processor group to a hyperscale firewall VDOM

The following FortiGate models support this feature and the sections linked below have been updated with this information:

October 24, 2022

New sections:

October 6, 2022

FortiOS 7.0.7 document release. Corrections to FortiGate-5001E and 5001E1 fast path architecture.

September 27, 2022

New information about NP7 DoS policy offloading limitations added to DoS policy hardware acceleration.

September 6, 2022

Added a disclaimer to CP9 capabilities.

August 11, 2022

Changes to the following sections:

July 21, 2022

Improvements to Configuring hyperscale TCP timeout profiles and Configuring hyperscale UDP timeout profiles.

July 12, 2022

New section: FortiGate 3700F and 3701F fast path architecture. More information about NP7 traffic shaping added to NP7 traffic shaping. Fixes to NTurbo and IPSA and IPSA offloads flow-based pattern matching.

June 7, 2022

FortiOS 7.0.6 Document release. For new features, see What's new in FortiOS 7.0.6.

May 6, 2022

Changes to config dsw-queue-dts-profile. New section: diagnose sys session list and no_ofld_reason field (NP7 session information).

April 29, 2022

Previous versions of this document incorrectly stated that NP6 processors support offloading DoS policy sessions. This has been corrected throughout the document as required. New section FortiGate 200F and 201F fast path architecture.

April 8, 2022

Corrections to FortiGate 400E Bypass fast path architecture.

April 6, 2022

New section: FortiGate 400E Bypass fast path architecture.

April 4, 2022

FortiOS 7.0.5 Document release. For new features, see What's new in FortiOS 7.0.5.

New sections:

March 1, 2022

Removed an incorrect statement from the section Increasing NP6 offloading capacity using link aggregation groups (LAGs).

Correction to Disabling NP offloading for firewall policies and Disabling nTurbo for firewall policies.

December 15, 2021

Moved information about improving CPS performance to sections describing the following FortiGate models that support this feature:

Removed information about older NP and CP processors and removed information about SP processors since older FortiGate models that include this hardware are not supported by FortiOS 6.4.

December 3, 2021

Corrections to FortiGate 80F, 81F, and 80F Bypass fast path architecture.

Correction to Disabling NP offloading for firewall policies.

New section Disabling nTurbo for firewall policies.

Removed the incorrect section "Disabling CP offloading for firewall policies".

More information added to NP6 session drift.

September 13, 2021

New section: FortiGate 80F, 81F, and 80F Bypass fast path architecture.

Added more information about the NP6XLite processor to Network processors (NP7, NP6, NP6XLite, and NP6Lite) and NP6XLite processors.

September 3, 2021

New and improved content:

August 4, 2021

Corrected errors in the section FortiGate 100F and 101F fast path architecture.

July 28, 2021

FortiOS 7.0.1 document release. For new features, see What's new in FortiOS 7.0.1.

Added a note about NP6 processors not offloading sessions between two EMAC VLANs on NPU inter-VDOM link interfaces to Using VLANs to add more accelerated inter-VDOM link interfaces.

Updated NTurbo offloads flow-based processing to clarify that NTurbo also applies to IPsec VPN sessions.

June 22, 2021

Updated NP6 session fast path requirements to list support for offloading UDP traffic with a destination port of 4500 (ESP-in-UDP traffic). New section: Offloading UDP-encapsulated ESP traffic.

Corrected integrated switch fabric information in the following sections:

April 12, 2021

Improved the information in Supporting IPsec anti-replay protection.

Corrected the output of the get hardware npu np6 port-list command in FortiGate 3600E and 3601E fast path architecture.

April 7, 2021

FortiOS 7.0 document release.

Change log

Change log

Date

Change description

February 21, 2023

Deleted an incorrect statement about NP7 support for SSL VPN encryption from Network processors (NP7, NP6, NP6XLite, and NP6Lite).

February 8, 2023

Added all relevant options and corrected the information about the NP7 hash-config option, see hash-config {src-dst-ip | 5-tuple | src-ip}. Added a note about setting the hash-config for the FortiGate-3500F and 3501F to FortiGate 3500F and 3501F fast path architecture.

New section: FortiGate 3200F and 3201F fast path architecture.

February 7, 2023

The dedicated management CPU feature is supported by the FortiGates with the NP6XLite (SOC4) processor. This information has been added to Improving GUI and CLI responsiveness (dedicated management CPU).

January 4, 2023

Corrected information about NTurbo support and interface policies, see NTurbo offloads flow-based processing.

Corrected the documented default values for many of the individual traffic types monitored by NP7 HPE, see NP7 HPE for individual traffic types.

New sections:

November 8, 2022

Described support for creating LAGs between interfaces connected to different NP6 processors for FortiGates with multiple NP6 processors and no internal switch fabric. For more information, see Increasing NP6 offloading capacity using link aggregation groups (LAGs). Assigning an NP7 processor group to a hyperscale firewall VDOM

The following FortiGate models support this feature and the sections linked below have been updated with this information:

October 24, 2022

New sections:

October 6, 2022

FortiOS 7.0.7 document release. Corrections to FortiGate-5001E and 5001E1 fast path architecture.

September 27, 2022

New information about NP7 DoS policy offloading limitations added to DoS policy hardware acceleration.

September 6, 2022

Added a disclaimer to CP9 capabilities.

August 11, 2022

Changes to the following sections:

July 21, 2022

Improvements to Configuring hyperscale TCP timeout profiles and Configuring hyperscale UDP timeout profiles.

July 12, 2022

New section: FortiGate 3700F and 3701F fast path architecture. More information about NP7 traffic shaping added to NP7 traffic shaping. Fixes to NTurbo and IPSA and IPSA offloads flow-based pattern matching.

June 7, 2022

FortiOS 7.0.6 Document release. For new features, see What's new in FortiOS 7.0.6.

May 6, 2022

Changes to config dsw-queue-dts-profile. New section: diagnose sys session list and no_ofld_reason field (NP7 session information).

April 29, 2022

Previous versions of this document incorrectly stated that NP6 processors support offloading DoS policy sessions. This has been corrected throughout the document as required. New section FortiGate 200F and 201F fast path architecture.

April 8, 2022

Corrections to FortiGate 400E Bypass fast path architecture.

April 6, 2022

New section: FortiGate 400E Bypass fast path architecture.

April 4, 2022

FortiOS 7.0.5 Document release. For new features, see What's new in FortiOS 7.0.5.

New sections:

March 1, 2022

Removed an incorrect statement from the section Increasing NP6 offloading capacity using link aggregation groups (LAGs).

Correction to Disabling NP offloading for firewall policies and Disabling nTurbo for firewall policies.

December 15, 2021

Moved information about improving CPS performance to sections describing the following FortiGate models that support this feature:

Removed information about older NP and CP processors and removed information about SP processors since older FortiGate models that include this hardware are not supported by FortiOS 6.4.

December 3, 2021

Corrections to FortiGate 80F, 81F, and 80F Bypass fast path architecture.

Correction to Disabling NP offloading for firewall policies.

New section Disabling nTurbo for firewall policies.

Removed the incorrect section "Disabling CP offloading for firewall policies".

More information added to NP6 session drift.

September 13, 2021

New section: FortiGate 80F, 81F, and 80F Bypass fast path architecture.

Added more information about the NP6XLite processor to Network processors (NP7, NP6, NP6XLite, and NP6Lite) and NP6XLite processors.

September 3, 2021

New and improved content:

August 4, 2021

Corrected errors in the section FortiGate 100F and 101F fast path architecture.

July 28, 2021

FortiOS 7.0.1 document release. For new features, see What's new in FortiOS 7.0.1.

Added a note about NP6 processors not offloading sessions between two EMAC VLANs on NPU inter-VDOM link interfaces to Using VLANs to add more accelerated inter-VDOM link interfaces.

Updated NTurbo offloads flow-based processing to clarify that NTurbo also applies to IPsec VPN sessions.

June 22, 2021

Updated NP6 session fast path requirements to list support for offloading UDP traffic with a destination port of 4500 (ESP-in-UDP traffic). New section: Offloading UDP-encapsulated ESP traffic.

Corrected integrated switch fabric information in the following sections:

April 12, 2021

Improved the information in Supporting IPsec anti-replay protection.

Corrected the output of the get hardware npu np6 port-list command in FortiGate 3600E and 3601E fast path architecture.

April 7, 2021

FortiOS 7.0 document release.